session-search

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Utilizes local command-line tools obsidian-wiki and grep to perform session queries and check file metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from historical agent session transcripts, creating a surface for indirect prompt injection.
  • Ingestion points: Transcript files are read from disk based on paths retrieved from the sessions-query command in SKILL.md (Step 4).
  • Boundary markers: No delimiters are defined to separate injected transcript content from the agent's primary instructions.
  • Capability inventory: The skill has the ability to execute shell commands (obsidian-wiki, grep) and run a Python script to parse file content.
  • Sanitization: Employs a Python script to filter for user-type turns, excludes metadata/sidechain turns, skips content beginning with < tags, and truncates the retrieved content to 400 characters per turn.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 01:26 AM
Security Audit — agent-trust-hub — session-search